Cloud Network Anomaly Detection via Dynamic Behavioral Profiling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity measures in cloud environments struggle to dynamically and automatically adapt to changing attack vectors and targets, particularly in complex and ever-changing environments where traditional security features like micro-segmentation and cloud-provider security groups cannot prevent abuse of permitted connections by external attackers or internal threats.
Innovation Solution
A method and system for detecting anomalous network activity using probabilistic unsupervised learning methods, which create and continuously update profiles of virtual entities' network behavior, allowing for the identification of deviations from expected behavior and potential security incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security features like micro-segmentation and cloud-provider security groups are used, then network connection control between workloads is improved, but the system cannot stop abuse of permitted connections by external attackers or internal threats
Solution Approach 1:
The patent implements dynamic baseline adjustment by continuously learning normal network behavior patterns from multiple sources (on-premises, cloud, hybrid environments) and adapting security policies in real-time. The system updates baselines based on changing organizational needs, seasonal patterns, and emerging threat landscapes, transforming static security groups into dynamic, adaptive security boundaries that automatically respond to abnormal behaviors while maintaining permitted connections.
2Reliability
If policies-enforcing security features are implemented to limit network connections, then security control is improved, but complex and ever-changing attack vectors cannot be dynamically adapted to
Solution Approach 1:
The patent implements comprehensive feedback loops by continuously monitoring network traffic, comparing observed behaviors against learned baselines, and automatically adjusting security policies based on detected anomalies. The system incorporates feedback from multiple environments (on-premises, cloud, hybrid) and uses machine learning to refine its understanding of normal versus abnormal behavior, enabling dynamic adaptation to new attack vectors while maintaining security control.
Solution Approach 2:
The patent performs preliminary action by proactively learning and establishing baselines of normal network behavior before attacks occur. The system continuously ingests data from various sources, pre-processes and normalizes information, and builds predictive models of expected behavior patterns. This preliminary preparation enables the system to quickly detect and respond to deviations from normal behavior, allowing dynamic adaptation to new attack vectors without waiting for incidents to occur.
3Stability of the object's composition
If traditional security protection methods are used, then established security boundaries are maintained, but rapid and automatic adaptation to changing attack vectors and targets is not achieved
Solution Approach 1:
The patent implements parameter changes by dynamically adjusting security policy parameters based on learned behavioral patterns and detected anomalies. The system modifies connection allowances, rate limits, and access rules in real-time based on changing threat landscapes and organizational needs. This enables rapid adaptation to new attack vectors while maintaining stable security boundaries through controlled, data-driven parameter adjustments rather than rigid static configurations.
Data Source
AI summary
A method and system for detecting anomalous network activity in a cloud-based compute environment. The method comprises receiving configuration data and network activity observations for a set of virtual entities in the cloud-based compute environment; creating a profile for each virtual entity in the set of virtual entities, when the virtual entity does not already have an associated profile; dynamically updating the virtual entity of a profile with the respective network activity observations of the virtual entity; and determining whether anomalies have been detected.


